Cybersecurity engineer here: I work for a defense company's data protection arm and you have NO IDEA how true this is. The really good companies spend almost as much in employee training as they do in software/hardware.
But you wanna know what's even a bigger problem than human stupidity? GREED I'd say about 50% of the companies out there have very little or no security because why invest in something that produces no profits?